20000906 Multiple Security Holes in LPPlusmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html CVE-2000-0881
LPPlus 3.2.2/3.3 - dccscan Unprivileged read
Record summary
CVE-2000-0881 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLPPlus 3.2.2/3.3 - dccscan Unprivileged readExploitDB exploitby Dixie FlatlineNot analyzed1 file
References
41644vdb entry
http://www.securityfocus.com/bid/1644 lpplus-dccscan-file-read(5201)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5201 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0881